Accidental Google Pixel Lock Screen Bypass
341–350 of 475 posts
Re: Accidental Google Pixel Lock Screen Bypass
#342Earlier quoted context omitted.
Presumably not all keys? If you receive a phone call while locked presumably the phone can still access the address book to display the contact name and photo? And music playing apps can presumably access their database of music to play songs whilst the phone is locked?
Could be reading a cached copy of the contact list since it’s not very big The music playing is a different story
Re: Accidental Google Pixel Lock Screen Bypass
#343Re: Accidental Google Pixel Lock Screen Bypass
#344Earlier quoted context omitted.
Could be reading a cached copy of the contact list since it’s not very big The music playing is a different story
Text messages (iMessages) can be displayed on lock screens. Not sure how they do that with encryption but maybe the notification is separate.
Re: Accidental Google Pixel Lock Screen Bypass
#345Re: Accidental Google Pixel Lock Screen Bypass
#346Re: Accidental Google Pixel Lock Screen Bypass
#347Appalling handling on Google’s end here. The duplicate issue part I can understand, but why should it take two reports of a critical vulnerability to take action? Surely when the first one comes through it’s something you jump on, fix and push out ASAP, not give delay to the point where a second user can come along, find the bug, and report it. The refactor that’s mentioned towards the end of the article is great, bu…
Quoted post unavailable.
Re: Accidental Google Pixel Lock Screen Bypass
#348Re: Accidental Google Pixel Lock Screen Bypass
#349> "Hopefully they treated the original reporter(s) fairly as well." Perhaps they should have reconsidered a bounty payment of some sort for the first bug reporter as well. Perhaps that's where the other $30k of the $100k went. This actually says something interesting about bug bounty programs in general: Given a high level of false positives, it's probably not uncommon AT ALL that sometimes it takes a couple of bug r…
This case was not the case of eventually the same reports being taken seriously. None of them were, until the author met people working at Google in person at some event, and him showing them the issue and then persisting.
Different than "Ops, we received a couple of requests, better look into it" and more like "this guy won't stop bothering us about it, probably should look into it".
Security reports from proper pentesters tend to include easy to reproduce steps and if you can't reproduce it yourself from that, you can ask them to expand, since it's in their interest for you to be able to understand them, since that's how they get paid.
Re: Accidental Google Pixel Lock Screen Bypass
#350Earlier quoted context omitted.
> Keeping the phones on and connected to a charger in the evidence lockers doesn't seem like too much work. There's no way that's a standard procedure.
Why? Seems pretty intuitive to me in a time where everything is encrypted.